THREAT OPS › Threat News › [NVD] CVE-2026-22221 (HIGH 8.0) — An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent
authenticated
attacker
execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in sever
[NVD] CVE-2026-22221 (HIGH 8.0) — An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in sever
CVE-2026-22221 CVSS: 8.0 HIGH Published: 2026-02-02T18:16:14.740
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent
authenticated
attacker
execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network secur
Indicators of compromise
- CVE-2026-22221cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-22221